Critical OpenVPN Zero-Day Flaws Affecting Millions of Endpoints Across the Globe

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have uncovered four zero-day vulnerabilities within OpenVPN, the world’s leading VPN solution. These vulnerabilities pose significant threats to millions of devices globally. These vulnerabilities, identified by the internal codename OVPNX, affect a wide range of operating systems including …

Operation PANDORA Shutdown 12 Fake Call Centers that Steal Over €10M

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Operation PANDORA has successfully dismantled a network of 12 fraudulent call centers, dealing a significant blow to a sophisticated criminal enterprise that has stolen over €10 million from unsuspecting victims. This landmark operation, spearheaded by Europol, marks a critical step …

CISA & FBI Release Urges Developers to Eliminate Directory Traversal Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) have issued a joint Secure by Design Alert, calling on software developers and industry executives to intensify their efforts in eliminating directory traversal vulnerabilities within their …

LayerX Security Raises $24M for its Browser Security Platform, Enabling Employees to Work Securely from Any Browser, Anywhere

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

LayerX, pioneer of the LayerX Browser Security platform, today announced $24 million in Series A funding led by Glilot+, the early-growth fund of Glilot Capital Partners, with participation from Dell Technologies Capital and other investors. Lior Litwak, Managing Partner at …

NCSC Warns of Russian Hackers Attacking Critical National Infrastructure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The National Cyber Security Centre (NCSC) has issued a stark warning about a new wave of cyber threats from Russian-aligned groups targeting the UK’s critical national infrastructure. Over the past 18 months, these groups have evolved, showing a solid ideological …

New macOS Adload Malware Bypasses Built-in macOS Antivirus Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new variant of the notorious Adload malware has been discovered to bypass the latest updates to Apple’s built-in antivirus, XProtect. Despite Apple’s efforts to fortify its defenses with a significant update to its malware signature list, Adload’s authors have …

World Password Day 2024: Create Strong Passwords & Stay Safe Online

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Today is an important day for online security as it marks World Password Day. This serves as a reminder to prioritize the use of strong and secure passwords to protect our online accounts and personal information from potential cyber threats. …

Beware! Threat Actors Selling RDO Access on Hacker Forums

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity communities are on high alert as threat actors have begun selling Remote Desktop Protocol (RDO) access on underground hacker forums. This alarming trend poses significant risks to individual and organizational cybersecurity, potentially allowing unauthorized access to sensitive information and …

Critical MailCleaner Vulnerabilities Let Attackers Execute arbitrary command

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Critical vulnerabilities in MailCleaner versions before 2023.03.14 allow remote attackers to take complete control of the appliance through malicious emails, administrator interaction with attacker sites or links, and exploitation of SOAP endpoints, which compromises the confidentiality and integrity of the …

Dropbox Sign Hacked: Attackers Stolen API Keys, MFA, & Hashed Passwords

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Dropbox disclosed a significant security breach affecting its electronic signature service, Dropbox Sign (formerly known as HelloSign). The incident, which came to light on April 24, involved unauthorized access to the Dropbox Sign production environment, exposing sensitive customer information. Dropbox’s …